RustDoor, also tracked as ThiefBucket, is a Rust-based macOS backdoor associated with North Korean threat activity, particularly clusters linked with BlueNoroff, Alluring Pisces, and Sapphire Sleet. It has been used in campaigns targeting cryptocurrency users, crypto businesses, and software developers, including social-engineering operations in which attackers impersonate recruiters or software vendors and deliver trojanized applications, fake updates, or booby-trapped development projects.
RustDoor is designed to establish persistent backdoor access on infected Macs while also supporting information theft. Observed activity shows it masquerading as legitimate software updates, including Visual Studio-themed lures, and being delivered through trojanized macOS applications or malicious project files. In some campaigns it was paired with additional payloads, including stealer malware and shell-based follow-on tooling, indicating use as part of a broader multi-stage intrusion chain.
Documented behavior includes host reconnaissance, theft of user and application data, and exfiltration of collected information to attacker-controlled infrastructure. Reported targeting has included browser-related data, cryptocurrency wallet material, and in at least one campaign data associated with the LastPass browser extension. RustDoor-linked operations have also attempted to download and execute secondary scripts to provide reverse-shell-style access or additional post-compromise capability.
RustDoor has been observed in infrastructure and code overlaps with other malware families and campaigns, including Koi Stealer, RustBucket, and broader DPRK crypto-targeting operations. Multiple assessments link it to financially motivated North Korean intrusion activity focused on cryptocurrency theft and access operations against organizations and individuals in the digital asset ecosystem. Its use of social engineering, signed or notarized macOS applications in related campaigns, and deceptive update-themed execution chains reflects continued adaptation to macOS security controls.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CISA and Microsoft confirmed on Tuesday that CVE-2026-68820 is being exploited... The vulnerability impacts Winsock... Check Point researchers explained that the malware first gathers information about the infected device before deploying an exploit for CVE-2026-68820.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Infrastructure overlap with ToneShell backdoor, Rustdoor and Koi stealer
“In this campaign, we discovered a Rust-based macOS malware nicknamed RustDoor masquerading as a legitimate software update…”
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The analysis of the script revealed an interesting and uncommon technique, namely to combine Python with Apple Scripting, as the filegrabber() function executes a large block of Apple script using the osascript -e command.
For two IPs of the ShadowSyndicate infrastructure, we found Cobalt strike beacons at the same timeframe that were linked to the Citrix bleed exploit attack campaign where Lockbit ransomware was chiefly deployed by affiliates.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a DPRK-attributed macOS malware whose crypto-wallet targeting list closely matches PHANTOMPULSE reconnaissance.
Rust-written macOS backdoor delivered via trojanized apps; described as linked to ransomware groups and designed to simplify cross-platform development.
Backdoor malware discussed through infrastructure and API-pattern overlap with ToneShell and Atomic/AMOS-related activity, especially in macOS-focused campaigns.
macOS backdoor mentioned only as an example of malicious domains tied to the investigated hosting ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.